Also known as: GOLD FEATHER
Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.(Citation: BushidoToken Qilin RaaS JUN 2024)(Citation: Sophos Qilin MSP APR 2025)
Executive Summary
Water Galura, also known as GOLD FEATHER, operates a Double extortion Ransomware-as-a-Service (RaaS) model since at least 2024. Primarily targeting sectors including healthcare and financial services across various countries, they demand ransom payments for decryption keys and additional fees to prevent data publication. Their operations leverage T1657 (Financial Theft), T1585.001 (Social Media Accounts), and T1486 (Data Encrypted for Impact) techniques.
Goals & Targeting
Water Galura targets industries with sensitive data, such as healthcare and finance, where the financial stakes are highest. Their geographic reach suggests a global approach, aiming for maximum disruption and payoff. Small businesses and medium-sized enterprises are particularly vulnerable, offering attractive yet defensible assets to extract high-value ransoms.
Enhanced Description
Water Galura are sophisticated cybercriminal operators of the Qilin RaaS platform, managing payload generation, ransom negotiations, and data leak sites. Since mid-2022, they've recruited affiliates on Russian forums, using double extortion to maximize revenue. Their operations typically involve encrypting victims' data, demanding ransoms for decryption keys, and additional fees to avoid public leaks of stolen information. Water Galura's strategic focus on high-value sectors ensures maximum impact on their targets.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Water Galura's campaigns often involve structured attacks on SMEs and critical sectors, using forums to recruit affiliates. Their operations include targeting countries in Eastern Europe and North America, leveraging double extortion for maximum impact, as seen in a late 2024 incident affecting healthcare providers.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate; information from Sophos and BushidoToken is reliable, but gaps remain in their recruitment tactics and initial attack methods beyond Qilin.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
3
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
2
Tactics